An Efficient Scheme to Detect Evil Twin Rogue Access Point Attack in 802.11 Wi-Fi Networks

被引:16
|
作者
Agarwal, Mayank [1 ]
Biswas, Santosh [2 ]
Nandi, Sukumar [2 ]
机构
[1] Ben Gurion Univ Negev, Dept ISE, Beer Sheva, Israel
[2] IIT Guwahati, Dept Comp Sci & Engn, Gauhati, India
关键词
Intrusion Detection System; Evil Twin Rogue Access Point Attack; WiFi networks; False alarms;
D O I
10.1007/s10776-018-0396-1
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The MAC layer of 802.11 protocol possess inherent weakness making it vulnerable to various security attacks like denial of service, deauthentication attack, flooding attacks, rogue access point (RAP) etc. In this manuscript we focus on evil twin attack. An evil twin is a RAP setup by cloning the MAC address and the Service Set IDentifier of an existing wireless access point (AP). An evil twin is setup so that the client(s) unknowingly connect to them under the pretext that they are connected to a genuine AP. Once a client is connected, an attacker eavesdrops on its communication to hijack client's communication, re-direct clients to malicious websites, steal credentials of the clients connecting to it. Existing methods to detect the evil twin include maintaining white lists, patching AP/client, timing based solutions, protocol modifications etc. These methods usually require extensive setup and maintenance, have scalability and compatibility issues, require changes in protocol stack making them expensive to deploy and manage. The network conditions under normal and evil twin attack are almost similar thereby crafting a signature or defining an anomaly pattern usually leads to large amount of false positives. In this manuscript, we propose an IDS for detecting the evil twin attack, which addresses most of these issues associated with the existing detection mechanisms. Further the scheme is also proved to detect a single evil twin, multiple evil twins for single AP and multiple evil twins for multiple APs. The proposed IDS has been deployed in a lab environment and its detection rate exceeds 92% mark and the accuracy is 100% in all the runs.
引用
收藏
页码:130 / 145
页数:16
相关论文
共 50 条
  • [21] An Autonomous Cognitive Access Point for Wi-Fi Hotspots
    Tamma, Bheemarjuna Reddy
    Manoj, B. S.
    Rao, Ramesh
    GLOBECOM 2009 - 2009 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-8, 2009, : 5572 - 5577
  • [22] Deploying Energy Efficient Wi-Fi Networks
    Morshedi, Maghsoud
    Noll, Josef
    2019 INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB), 2019,
  • [23] De-Authentication Attack Detection using Discrete Event Systems in 802.11 Wi-Fi Networks
    Seth, Abhay Deep
    Biswas, Santosh
    Dhar, Amit Kumar
    13TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATION SYSTEMS (IEEE ANTS), 2019,
  • [24] Wi-Fi Network Testing Using an Integrated Evil-Twin Framework
    Esser, Andre
    Serrao, Carlos
    2018 FIFTH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS: SYSTEMS, MANAGEMENT AND SECURITY, 2018, : 216 - 221
  • [25] Green Frame Aggregation Scheme for Wi-Fi Networks
    Alaslani, Maha
    Showail, Ahmad
    Shihada, Basem
    2015 IEEE 16TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (HPSR), 2015, : 22 - 27
  • [26] Modeling of Preemptive Channel Access in Wi-Fi Networks
    Riterman, A. V.
    Bankov, D. V.
    Lyakhov, A. I.
    Khorov, E. M.
    PROBLEMS OF INFORMATION TRANSMISSION, 2024, 60 (04) : 327 - 343
  • [27] Detecting and blocking unauthorized access in wi-fi networks
    Xia, HD
    Brustoloni, J
    NETWORKING 2004: NETWORKING TECHNOLOGIES, SERVICES, AND PROTOCOLS; PERFORMANCE OF COMPUTER AND COMMUNICATION NETWORKS; MOBILE AND WIRELESS COMMUNICATIONS, 2004, 3042 : 795 - 806
  • [28] Gateway independent user-side wi-fi Evil Twin Attack detection using virtual wireless clients
    Nakhila, Omar
    Amjad, Muhammad Faisal
    Dondyk, Erich
    Zou, Cliff
    COMPUTERS & SECURITY, 2018, 74 : 41 - 54
  • [29] Design of an enhanced access point to optimize TCP performance in Wi-Fi hotspot networks
    Bruno, Raffaele
    Conti, Marco
    Gregori, Enrico
    WIRELESS NETWORKS, 2007, 13 (02) : 259 - 274
  • [30] Quality of Service Oriented Access Point Selection Framework for Large Wi-Fi Networks
    Raschella, Alessandro
    Bouhafs, Faycal
    Seyedebrahimi, Mirghiasaldin
    Mackay, Michael
    Shi, Qi
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (02): : 441 - 455